CyberRota Analysis
AI-GeneratedThe vulnerability affects Coder's remote development environment provisioning via Terraform, where improper handling of the `email_verified` claim can lead to account takeover if the claim is returned as a non-boolean or omitted. This flaw allows attackers to exploit the system's fallback mechanism for email-based account linking, potentially compromising user accounts. Organizations using affected versions should prioritize upgrading to versions 2.29.7, 2.32.7, 2.33.8, or 2.34.2 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-based account fallback, this enabled account takeover. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 coerces `email_verified` across bool, string and numeric types (fail-closed) and blocks the email fallback when the matched user already has a different linked IdP subject. As a workaround, ensure the IdP returns `email_verified` as a native JSON boolean. The email-fallback linking issue has no configuration workaround; upgrading is required.
Related CVEs
Other vulnerabilities affecting the same vendor(s)